
Dokploy's CVE-2026-27130: OS Command Injection via the appName Parameter in a Popular Self-Hosted PaaS, and What It Means to Trust a Deploy Tool With Root on Your Fleet
Dokploy's CVSS 9.9 command injection through the appName field, why it's the second time that field has been the entry point, and why the same bug class keeps recurring across self-hosted PaaS deploy tools.

What You See Is What You Sign: Inside Ethereum's Plan to Kill the $1.5B Blind-Signing Problem
The Ethereum Foundation's Clear Signing standard (ERC-7730) wants to end blind signing — the UX flaw behind the $1.5B Bybit hack and years of wallet-drainer phishing. Here's how it works, what it can't fix, and why it matters for builders.

Q1 2026 Crypto Security Report: How the $1.5B Bybit Hack Signals a New Era of Infrastructure Attacks
Q1 2026 saw $2 billion in crypto losses as attackers abandoned smart contract exploits for supply chain attacks, social engineering, and DNS hijacks. The $1.5B Bybit breach and $286M Drift Protocol hack reveal a new threat model requiring full-stack security beyond Solidity auditing.

The $1.5 Billion Wake-Up Call: How Supply Chain Attacks Became Web3's Deadliest Threat in 2025
In 2025, software supply chain attacks claimed $1.45 billion from just two incidents — more than any other Web3 attack vector. From the Bybit heist to 454,000 malicious npm packages, here's what changed, why smart contract audits missed it all, and what the industry must do before the next billion-dollar breach.

The $1.22 Hack: Ledger's CTO Says AI Has Broken Crypto Security Economics
Ledger CTO Charles Guillemet warns that AI has collapsed the cost of crafting smart-contract exploits to dollars per attack — and the industry's audit-first defenses no longer keep pace.

Vercel + Lovable Breaches: How AI Tools Became Web3's New Supply Chain Risk
April 2026's Vercel and Lovable breaches reveal how AI productivity tools became privileged identities inside Web3's developer toolchain — and why frontend security is the layer crypto forgot to audit.

Treasury OCCIP Brings Crypto Into the Federal Cyber Defense Perimeter
On April 10, 2026, the US Treasury's OCCIP gave digital asset firms the same federal cyber threat intelligence that banks receive — a quiet but structural shift that reframes crypto as critical financial infrastructure.

When Hackers Become Coworkers: Inside the Six-Month North Korean Operation That Drained $285M From Drift Protocol
North Korean operatives spent six months posing as a quant trading firm to compromise Drift Protocol's Security Council, then drained $285M in 12 minutes by exploiting Solana's durable nonces. Why DeFi's audit and multisig defenses fail against nation-state insider threats.

Smart Contracts Got Safer, Crypto Got Worse: Inside Q1 2026's Infrastructure Attack Era
DeFi smart contract exploits dropped 89% in Q1 2026, yet crypto still lost roughly $450M. The Trezor, Resolv Labs, and Drift Protocol incidents show why audits no longer cover the real attack surface.